
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27100 is a build information disclosure vulnerability in Jenkins core affecting the Run Parameter handling mechanism. Jenkins 2.550 and earlier (weekly) and LTS 2.541.1 and earlier accept Run Parameter values that reference builds the submitting user does not have access to, enabling unauthorized enumeration of job and build metadata. It was disclosed on February 18, 2026, as part of a Jenkins security advisory and was reported through the Jenkins Bug Bounty Program sponsored by the European Commission. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-551 (Incorrect Behavior Order: Authorization Before Parsing and Canonicalization), meaning Jenkins processes and accepts Run Parameter values before properly validating whether the requesting user has permission to access the referenced build. An authenticated attacker with Item/Build and Item/Configure permissions can craft a build submission that references builds in jobs outside their authorized scope, and Jenkins will respond with information confirming or denying the existence of those jobs/builds, as well as their display names if they exist. The attack vector is network-based, requires low privileges, and no user interaction (Jenkins Advisory).
Successful exploitation allows an attacker to perform reconnaissance against the Jenkins infrastructure beyond their assigned permissions — specifically, they can enumerate the existence of restricted jobs, confirm or deny the existence of specific builds, and retrieve display names of builds they are not authorized to view. While there is no direct code execution, integrity, or availability impact, the information gained can facilitate further targeted attacks or expose sensitive CI/CD pipeline structure details (Jenkins Advisory, Red Hat Bugzilla).
Jenkins has released fixed versions that reject Run Parameter values referencing builds the submitting user cannot access: update to Jenkins weekly 2.551 or Jenkins LTS 2.541.2 (Jenkins Advisory). As an interim measure, restrict Item/Build and Item/Configure permissions to only trusted users, and apply the principle of least privilege across all Jenkins roles. Monitor Jenkins logs for anomalous Run Parameter usage patterns referencing out-of-scope builds. Red Hat has also tracked this issue for affected products (Red Hat Bugzilla).
The vulnerability was reported through the Jenkins Bug Bounty Program sponsored by the European Commission, with credit given to Suman Roy for the discovery (Jenkins Advisory). Several security news outlets covered the advisory, though most coverage conflated it with the higher-severity XSS vulnerability (CVE-2026-27099) disclosed in the same advisory. Community reaction has been relatively muted given the medium severity and the requirement for pre-existing authenticated access.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."